3Commas Faces Class Action Over $22M Crypto Losses Due to Alleged Cybersecurity Failures
A divided three-judge panel of the U.S. Court of Appeals for the Ninth Circuit has ruled that 3Commas, a provider of automated cryptocurrency trading services, must face a proposed class action in a California federal court. The lawsuit alleges that the company’s negligent cybersecurity measures led to nearly $22 million in losses for cryptocurrency owners.
The Ninth Circuit reversed a lower court’s dismissal of the case on jurisdictional grounds, determining that 3Commas had sufficient contacts with California to establish the court’s authority. The company offers trading "bots" that execute automated transactions across at least 14 cryptocurrency platforms.
The revived lawsuit centers on claims that 3Commas failed to implement adequate security protections, resulting in substantial financial harm to users. The case will now proceed in California for further legal proceedings.
3Commas.io cybersecurity rating report: https://www.rankiteo.com/company/3commas-io
"id": "3CO1772490558",
"linkid": "3commas-io",
"type": "Cyber Attack",
"date": "3/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Cryptocurrency owners using '
'automated trading bots',
'industry': 'Cryptocurrency / FinTech',
'location': 'California, USA',
'name': '3Commas',
'type': 'Company'}],
'description': 'A divided three-judge panel of the U.S. Court of Appeals for '
'the Ninth Circuit has ruled that 3Commas must face a proposed '
'class action in a California federal court. The lawsuit '
'alleges that the company’s negligent cybersecurity measures '
'led to nearly $22 million in losses for cryptocurrency '
'owners.',
'impact': {'financial_loss': '$22 million',
'legal_liabilities': 'Class action lawsuit',
'systems_affected': 'Automated cryptocurrency trading bots'},
'investigation_status': 'Ongoing (legal proceedings)',
'post_incident_analysis': {'root_causes': 'Alleged negligent cybersecurity '
'measures'},
'references': [{'source': 'U.S. Court of Appeals for the Ninth Circuit'}],
'regulatory_compliance': {'legal_actions': 'Class action lawsuit'},
'title': '3Commas Faces Class Action Over $22M Crypto Losses Due to Alleged '
'Cybersecurity Failures',
'type': 'Data Breach / Cybersecurity Failure',
'vulnerability_exploited': 'Inadequate security protections'}